fix: hardening round from code review (4 P1 + 15 P2)
CI / typecheck + test + build (windows) (push) Canceled after 0s
CI / typecheck + test + build (windows) (push) Canceled after 0s
P1: - settingsStore: back up an unparseable settings.json to .bak before falling back to defaults, so the next mutation can no longer silently wipe custom themes/highlight rules - ptyDispatcher: fan out per-session data/exit handlers (Set instead of a single slot) so SSH split panes stop stealing each other's stream - FilePanel: monotonic refresh token keeps stale listings from painting over a newer navigation; upload finish no longer yanks the panel back - settings.css: active settings-tab label derives from --chrome-fg so it stays visible on the shipped light themes P2 (main/renderer): - paste guard: a paste ending in a newline always confirms - Workspace: closing an SSH pane no longer seeds the local cwd with a remote path - tray: skip close-dialog continuation on a destroyed window - commands: close zombie 'in-progress' session logs at hydrate - zmodem: clear the stale offer timer before arming a new one - connectionsStore: coerce/validate renderer input before persisting - sftp: OperationError marker class keeps translated errors out of the transport-retry classifier - CommandsPanel: surface save failures inside the dialog - ConnectionSidebar: drop a tautological tooltip condition P2 (i18n/tooling/tests): - localize the 16 ANSI color labels and the highlight sample text (21 new keys across zh-CN/zh-TW/en/ja) - sync-changelog: keep ### subheadings, normalize CRLF notes - release.cjs: GitHub release reuse-by-tag (idempotent re-runs); fail loudly on a failed Gitea asset listing - commands-store test: absent historyEnabled now truly tests absence
This commit is contained in:
1 parent
33efbe921e
commit
4e5377f49c
27 files changed
+356
-83
No files matched your search
@@ -20,6 +20,41 @@ import { writeJson } from './store'
|
||||
const ENC_SUFFIX = '_enc'
|
||||
const PLAIN_PREFIX = 'plain:'
|
||||
const SECRET_KEYS = ['password', 'keyContent', 'passphrase'] as const
|
||||
const AUTH_METHODS: ReadonlySet<string> = new Set(['password', 'privateKey', 'agent'])
|
||||
|
||||
/**
|
||||
* Runtime coercion for renderer-supplied connection fields. saveConnection
|
||||
* copies input values verbatim, and they flow straight into ssh2's
|
||||
* ConnectConfig (port, keepalive) — a malformed save or a renderer regression
|
||||
* must not persist `port: "22"` or a NaN-bound keepalive. Repair over drop,
|
||||
* like every other store: strings stay strings, numbers are range-checked,
|
||||
* unknown auth falls back to password, optional fields collapse to undefined.
|
||||
*/
|
||||
function coerceConnectionInput(input: SshConnectionInput): SshConnectionInput {
|
||||
const out = { ...input } as Record<string, unknown>
|
||||
out.name = typeof input.name === 'string' ? input.name : ''
|
||||
out.group = typeof input.group === 'string' && input.group !== '' ? input.group : undefined
|
||||
out.host = typeof input.host === 'string' ? input.host.trim() : ''
|
||||
out.username = typeof input.username === 'string' ? input.username : ''
|
||||
const port = Number(input.port)
|
||||
out.port = Number.isInteger(port) && port >= 1 && port <= 65535 ? port : 22
|
||||
out.auth = AUTH_METHODS.has(input.auth as string) ? input.auth : 'password'
|
||||
out.askPasswordAtConnect = input.askPasswordAtConnect === true
|
||||
out.askPassphraseAtConnect = input.askPassphraseAtConnect === true
|
||||
out.keyPath =
|
||||
typeof input.keyPath === 'string' && input.keyPath !== '' ? input.keyPath : undefined
|
||||
const keepalive = Number(input.keepaliveIntervalSec)
|
||||
out.keepaliveIntervalSec =
|
||||
Number.isFinite(keepalive) && keepalive >= 0 ? Math.round(keepalive) : 0
|
||||
out.highlightProfileId =
|
||||
typeof input.highlightProfileId === 'string' && input.highlightProfileId !== ''
|
||||
? input.highlightProfileId
|
||||
: undefined
|
||||
for (const key of SECRET_KEYS) {
|
||||
if (out[key] !== undefined && typeof out[key] !== 'string') out[key] = undefined
|
||||
}
|
||||
return out as unknown as SshConnectionInput
|
||||
}
|
||||
|
||||
/** Internal persisted record: public fields + encrypted secret fields. */
|
||||
interface StoredConnection {
|
||||
@@ -150,7 +185,8 @@ export class ConnectionsStore {
|
||||
return stored ? decrypt(stored[encField] as string | undefined) : undefined
|
||||
}
|
||||
|
||||
saveConnection(input: SshConnectionInput): SshConnection {
|
||||
saveConnection(rawInput: SshConnectionInput): SshConnection {
|
||||
const input = coerceConnectionInput(rawInput)
|
||||
const list = this.load()
|
||||
let stored: StoredConnection | undefined
|
||||
|
||||
|
||||
Reference in new issue
Block a user